A new CSA survey of 900+ security leaders finds most breaches involve vulnerabilities teams already knew about
A new report has identified a critical gap in how organizations handle known cybersecurity flaws. In a survey of more than 900 security leaders, the Cloud Security Alliance found that more than 80% of businesses that failed to patch a known exploit within 24 hours of first discovering it have suffered a security incident directly tied to that flaw.
This finding in the CSA's 2026 State of Modern Application & AI Security report suggests that the vast majority of businesses don't move fast enough to patch security issues during the critical exposure window that opens the moment a new vulnerability is first discovered. That gap between disclosure and remediation is exactly what real-time runtime detection is built to cover, and it's why Wiz has been integrating that capability into its existing cloud posture and vulnerability scanning tools.
What the CSA finding implies is that so-called zero-day vulnerabilities, which lay undiscovered by researchers, are not the only concern for security teams. Rather, a significant number of security incidents stem from publicly known flaws surfaced during routine checks that simply aren’t remediated quickly enough.
While posture management scanning and vulnerability detection tools are being used effectively to catalog infrastructure misconfigurations and bugs in application code, far too many organizations fail to act on these findings promptly. Cyberattackers are aware of this, and they’re increasingly taking advantage of those critical days between a vulnerability’s disclosure and the deployment of a patch, during which time systems are critically exposed.
Part of the problem is that the two sides of this equation move at very different speeds. AI tools are helping developers find far more bugs than they can realistically fix, and that widening gap between discovery and remediation is exactly the window this report says attackers are exploiting.
Even more alarming is that many organizations have no way of knowing when an attacker is breaching their systems. The CSA’s survey found that 82% of organizations have not implemented effective runtime visibility across their IT environments. In other words, they’re unable to see when their live systems are under attack. They might know they’re vulnerable, but they can’t tell if anyone is taking advantage of these flaws. Because of this, most security teams are forced to treat every common vulnerability and exposure as a critical emergency, but this is a flawed strategy, as it means they cannot determine which flaws they should prioritize in their remediation efforts.
The findings from the report are likely to be rather awkward for a cloud security industry that has long claimed that agentless posture scanning and live runtime threat detection tools are fundamentally incompatible with one another.
For years, most security vendors have reinforced the message that companies face a stark choice when choosing a cloud-native application protection platform – either they go for lightweight, agentless scanning tools to detect vulnerabilities in their infrastructure and application code through regular snapshots, or adopt resource-intensive agents to monitor runtime environments in real time. The advantage of the former is that it keeps operational overheads to a minimum, while the latter offers more comprehensive protection at the cost of a significant performance hit.
However, the report suggests that this either-or choice is now an unacceptable tradeoff. Organizations without runtime protection are almost certain to suffer a breach from a known vulnerability at some point, simply because they have no way of knowing if it's being exploited while they work to patch it.
Perhaps the most concerning aspect of the CSA’s report is that it points to a widespread lack of awareness that organizations no longer have to accept this tradeoff. Wiz is one example of a vendor addressing it directly. The Wiz Sensor tool integrates runtime detection into the same platform that already performs configuration and vulnerability scanning, so a live-attack alert arrives connected to that existing context rather than as a standalone signal.
Of course, Wiz isn’t the only vendor working to close the gap between agentless scanning and resource-intensive runtime protection. The industry is pursuing two distinct approaches to this challenge. Agentless-first cloud security players are expanding their capabilities with the addition of runtime detection tools atop of their posture management platforms. Orca Security, another major provider of agentless security, has also embedded live-attack detection tools onto its platform.
Then there are the runtime-native security firms, led by Miggo Security and Upwind Security. Miggo has developed a detection and response platform that aims to mitigate attacks against known vulnerabilities before they can be patched. Similarly, Upwind built runtime detection as the foundation of its platform.
While both approaches have their proponents, the key differentiator is what happens once a threat has been identified. Standalone runtime detection tools are optimized to identify when an attack is in progress, but the lack of integration with an organization’s broader cloud posture and exposure context can be detrimental to defenders. Without this context, the onus is on human security pros to dig into the alert and determine how a vulnerability is being exploited and what systems, servers and data is at risk.
On the other hand, CNAPP-native platforms that integrate runtime detection can provide this context right off the bat. When Wiz Sensor flags an attack, it also draws on its existing map of the organization’s cloud posture to show the exposure paths already available to that workload, as well as the data it can reach. This kind of built-in context is what actually prevents serious data breaches, as the CSA report makes clear that while speed of detection is today’s problem, time to remediation will be the next critical gap organizations need to close.
The biggest takeaway from the CSA’s report is that organizations need to rethink how they evaluate their IT security stacks. Teams need to stop thinking in terms of either agentless or runtime security, because it’s now possible to have both. In an age where cybercriminals can and do use AI to generate exploit scripts in a matter of minutes, the real question is whether or not security teams are able to detect when known, unpatched vulnerabilities are actively being exploited.
People Also Ask
What did the CSA report find about cloud security incidents?
Over 80% of businesses that failed to patch critical vulnerabilities within 24-hours went on to experience a security incident related to that discovery. That’s because 82% of organizations lack visibility into their runtime environments.
Is finding vulnerabilities the same as preventing security incidents?
No. The report found that robust posture and vulnerability scanning isn’t enough to prevent security breaches. The majority of security incidents involved known vulnerabilities that weren’t closed in time.
What is the difference between agentless CNAPP and runtime protection?
CNAPP platforms use agentless scanning tools to identify misconfigurations and code vulnerabilities prior to deployment and at regular intervals. Runtime detection involves the continuous monitoring of live systems to detect exploits when attackers strike. The CSA data suggests that organizations need both, rather than one or another, to protect their systems.
Can cloud security platforms detect runtime threats, not just known vulnerabilities?
Increasingly, CNAPP platforms are integrating runtime detection layers with their agentless scanning tools to alert users to exploits against known but unpatched vulnerabilities.